Ransomware victim disclosure
← All victimsMCO
Claimed by fulcrumsec · listed 19 days ago
Status timeline
- Listed
May 1, 2026
- Data leaked
At a glance
- Group
- fulcrumsec
- Status
- Data leaked
- Sector
- Financial Services
- Listed on leak site
- May 1, 2026
About the victim
AI dossier — public-source company profileMCO is an organization operating in the financial services sector, as classified by the threat-intel source. The acronym is highly ambiguous and shared by multiple entities across jurisdictions; no public site content was available to disambiguate. Specific details about its operations, location, or scale cannot be reliably established from the available evidence.
- Industry
- Financial Services
Attack summary
Severity: medium — Data is reported as published (data_published status) in a financial services context, which elevates severity above low; however, the extreme ambiguity of the victim identity, absence of any proof file count, no stated data size, and an AI-generated/uninformative leak post prevent a higher classification.The group 'fulcrumsec' claims to have disclosed data relating to MCO, with the post status recorded as 'data_published', indicating exfiltration and publication of data. No further detail on the nature of the data or the scope of the attack is available from the truncated leak post.
Original description
AI-summarised, not from the leak postN/A The acronym "MCO" is too ambiguous to identify a specific company with confidence. Multiple organizations share this abbreviation across different industries and countries. Please provide additional context such as the full company name, industry, or country of operation to allow for an accurate and reliable description.
The leak post
captured from the group's siteFulcrumSec Browse victim listings from our recent concept campaigns: Index of /Shame Coming Soon: The Hardcoded Horror Show SLOPOCALYPSE NOW [email protected] Session: 05dc2052b7a29d8661f30cbf0ae4f2093e8c85324a16867df5dd5c24f0364d8b27 Tox: 969F8BE40B09537CD2A5038B9DA4BADE71C5F35DD666CC0D7632A6812D7AF72626D422D22540
Sources
Source
Indexed 19 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
